| Category | Package | Started | Completed | Duration | Options | Logs | ||||
|---|---|---|---|---|---|---|---|---|---|---|
| FILE | ps1 | 2026-05-28 20:03:28 | 2026-05-28 20:05:39 | 131s |
|
|||||
| Reports | JSON | |||||||||
interactive=1
nohuman=yes
vnc_port=5910
2026-05-28 19:52:07,764 [root] INFO: Date set to: 20260528T20:03:36, timeout set to: 200
2026-05-28 20:03:36,013 [root] DEBUG: Starting analyzer from: C:\6lreqs2g
2026-05-28 20:03:36,014 [root] DEBUG: Storing results at: C:\JzexnPnz
2026-05-28 20:03:36,014 [root] DEBUG: Pipe server name: \\.\PIPE\pLUQhYqI
2026-05-28 20:03:36,014 [root] DEBUG: Python path: C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64
2026-05-28 20:03:36,015 [root] INFO: analysis running as an admin
2026-05-28 20:03:36,015 [root] INFO: analysis package specified: "ps1"
2026-05-28 20:03:36,015 [root] DEBUG: importing analysis package module: "modules.packages.ps1"...
2026-05-28 20:03:36,027 [root] DEBUG: imported analysis package "ps1"
2026-05-28 20:03:36,027 [root] DEBUG: initializing analysis package "ps1"...
2026-05-28 20:03:36,027 [lib.common.common] INFO: no wrapping
2026-05-28 20:03:36,028 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 20:03:36,028 [root] DEBUG: New location of moved file: C:\Users\admin\AppData\Local\Temp\test-serial.ps1
2026-05-28 20:03:36,028 [root] INFO: Analyzer: Package modules.packages.ps1 does not specify a dll option
2026-05-28 20:03:36,028 [root] INFO: Analyzer: Package modules.packages.ps1 does not specify a dll_64 option
2026-05-28 20:03:36,028 [root] INFO: Analyzer: Package modules.packages.ps1 does not specify a loader option
2026-05-28 20:03:36,028 [root] INFO: Analyzer: Package modules.packages.ps1 does not specify a loader_64 option
2026-05-28 20:03:36,046 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser"
2026-05-28 20:03:36,060 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig"
2026-05-28 20:03:36,089 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise"
2026-05-28 20:03:36,094 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human"
2026-05-28 20:03:36,096 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2026-05-28 20:03:36,097 [lib.api.screenshot] ERROR: No module named 'PIL'
2026-05-28 20:03:36,097 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots"
2026-05-28 20:03:36,098 [root] DEBUG: Imported auxiliary module "modules.auxiliary.tlsdump"
2026-05-28 20:03:36,099 [root] DEBUG: Initialized auxiliary module "Browser"
2026-05-28 20:03:36,099 [root] DEBUG: attempting to configure 'Browser' from data
2026-05-28 20:03:36,108 [root] DEBUG: module Browser does not support data configuration, ignoring
2026-05-28 20:03:36,109 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.browser"...
2026-05-28 20:03:36,109 [root] DEBUG: Started auxiliary module modules.auxiliary.browser
2026-05-28 20:03:36,109 [root] DEBUG: Initialized auxiliary module "DigiSig"
2026-05-28 20:03:36,111 [root] DEBUG: attempting to configure 'DigiSig' from data
2026-05-28 20:03:36,111 [root] DEBUG: module DigiSig does not support data configuration, ignoring
2026-05-28 20:03:36,111 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.digisig"...
2026-05-28 20:03:36,111 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature
2026-05-28 20:03:36,187 [modules.auxiliary.digisig] DEBUG: File is not signed
2026-05-28 20:03:36,187 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2026-05-28 20:03:36,202 [root] DEBUG: Started auxiliary module modules.auxiliary.digisig
2026-05-28 20:03:36,203 [root] DEBUG: Initialized auxiliary module "Disguise"
2026-05-28 20:03:36,203 [root] DEBUG: attempting to configure 'Disguise' from data
2026-05-28 20:03:36,204 [root] DEBUG: module Disguise does not support data configuration, ignoring
2026-05-28 20:03:36,204 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.disguise"...
2026-05-28 20:03:36,208 [modules.auxiliary.disguise] INFO: Launched background process notepad.exe hidden (PID: 7432)
2026-05-28 20:03:36,208 [modules.auxiliary.disguise] INFO: Disguising GUID to f1c50e81-39fa-4714-bd08-67309103df6c
2026-05-28 20:03:36,208 [root] DEBUG: Started auxiliary module modules.auxiliary.disguise
2026-05-28 20:03:36,209 [root] DEBUG: Initialized auxiliary module "Human"
2026-05-28 20:03:36,209 [root] DEBUG: attempting to configure 'Human' from data
2026-05-28 20:03:36,209 [root] DEBUG: module Human does not support data configuration, ignoring
2026-05-28 20:03:36,209 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.human"...
2026-05-28 20:03:36,210 [root] DEBUG: Started auxiliary module modules.auxiliary.human
2026-05-28 20:03:36,210 [root] DEBUG: Initialized auxiliary module "Screenshots"
2026-05-28 20:03:36,210 [root] DEBUG: attempting to configure 'Screenshots' from data
2026-05-28 20:03:36,213 [root] DEBUG: module Screenshots does not support data configuration, ignoring
2026-05-28 20:03:36,213 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.screenshots"...
2026-05-28 20:03:36,214 [modules.auxiliary.screenshots] WARNING: Python Image Library is not installed, screenshots are disabled
2026-05-28 20:03:36,214 [root] DEBUG: Started auxiliary module modules.auxiliary.screenshots
2026-05-28 20:03:36,214 [root] DEBUG: Initialized auxiliary module "TLSDumpMasterSecrets"
2026-05-28 20:03:36,215 [root] DEBUG: attempting to configure 'TLSDumpMasterSecrets' from data
2026-05-28 20:03:36,215 [root] DEBUG: module TLSDumpMasterSecrets does not support data configuration, ignoring
2026-05-28 20:03:36,215 [root] DEBUG: Trying to start auxiliary module "modules.auxiliary.tlsdump"...
2026-05-28 20:03:36,217 [modules.auxiliary.tlsdump] WARNING: Unable to find lsass.exe process
2026-05-28 20:03:36,217 [root] DEBUG: Started auxiliary module modules.auxiliary.tlsdump
2026-05-28 20:03:36,217 [root] INFO: Interactive mode enabled - injecting into explorer shell
2026-05-28 20:03:36,267 [lib.api.process] INFO: Monitor config for process 4372: C:\6lreqs2g\dll\4372.ini
2026-05-28 20:03:36,267 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:36,270 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:36,286 [root] DEBUG: Loader: Injecting process 4372 with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:36,438 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:36,440 [root] DEBUG: 4372: Disabling sleep skipping.
2026-05-28 20:03:36,441 [root] DEBUG: 4372: Interactive desktop enabled.
2026-05-28 20:03:36,442 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:03:36,444 [root] DEBUG: 4372: Interactive desktop - injecting Explorer Shell
2026-05-28 20:03:36,449 [root] DEBUG: 4372: YaraInit: Compiled 44 rule files
2026-05-28 20:03:36,450 [root] DEBUG: 4372: YaraInit: Compiled rules saved to file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:36,487 [root] DEBUG: 4372: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:36,488 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:03:36,574 [root] DEBUG: 4372: Monitor initialised: 64-bit capemon loaded in process 4372 at 0x00007FFEAF1A0000, thread 1492, image base 0x00007FF65F9E0000, stack from 0x000000000A7C1000-0x000000000A7D0000
2026-05-28 20:03:36,575 [root] DEBUG: 4372: Commandline: C:\Windows\Explorer.EXE
2026-05-28 20:03:36,589 [root] DEBUG: 4372: Hooked 69 out of 69 functions
2026-05-28 20:03:36,620 [root] DEBUG: 4372: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:36,632 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:03:36,632 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:36,634 [lib.api.process] INFO: Injected into 64-bit <Process 4372 explorer.exe>
2026-05-28 20:03:40,078 [root] DEBUG: 4372: caller_dispatch: Added region at 0x00007FF65F9E0000 to tracked regions list (combase::CoCreateInstance returns to 0x00007FF65FA49D10, thread 4584).
2026-05-28 20:03:40,079 [root] DEBUG: 4372: YaraScan: Scanning 0x00007FF65F9E0000, size 0x545316
2026-05-28 20:03:40,112 [root] DEBUG: 4372: ProcessImageBase: Main module image at 0x00007FF65F9E0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:42,490 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE86B0000: C:\Windows\system32\twext (0x33000 bytes).
2026-05-28 20:03:42,591 [lib.api.process] INFO: Monitor config for process 4372: C:\6lreqs2g\dll\4372.ini
2026-05-28 20:03:42,592 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:42,595 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:42,602 [root] DEBUG: Loader: Injecting process 4372 with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:42,603 [root] DEBUG: 4372: caller_dispatch: Added region at 0x00000000027A0000 to tracked regions list (ntdll::LdrLoadDll returns to 0x00000000027A0043, thread 4984).
2026-05-28 20:03:42,604 [root] DEBUG: 4372: DumpPEsInRange: Scanning range 0x00000000027A0000 - 0x00000000027A0134.
2026-05-28 20:03:42,605 [root] DEBUG: 4372: ScanForDisguisedPE: Size too small: 0x134 bytes
2026-05-28 20:03:42,608 [lib.common.results] INFO: Uploading file C:\JzexnPnz\CAPE\4372_24477423029552026 to CAPE\82695f2ec3330791ae4dc42e03fc155a8015e79de09c2615c388b469ce58339d; Size is 308; Max size: 100000000
2026-05-28 20:03:42,616 [root] DEBUG: 4372: DumpMemory: Payload successfully created: C:\JzexnPnz\CAPE\4372_24477423029552026 (size 308 bytes)
2026-05-28 20:03:42,617 [root] DEBUG: 4372: DumpRegion: Dumped entire allocation from 0x00000000027A0000, size 4096 bytes.
2026-05-28 20:03:42,618 [root] DEBUG: 4372: ProcessTrackedRegion: Dumped region at 0x00000000027A0000.
2026-05-28 20:03:42,620 [root] DEBUG: 4372: YaraScan: Scanning 0x00000000027A0000, size 0x134
2026-05-28 20:03:42,622 [root] DEBUG: 4372: Monitor config - unrecognised key host-ip.
2026-05-28 20:03:42,622 [root] DEBUG: 4372: Monitor config - unrecognised key host-port.
2026-05-28 20:03:42,623 [root] DEBUG: 4372: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:42,624 [root] DEBUG: 4372: Dropped file limit defaulting to 100.
2026-05-28 20:03:42,650 [root] DEBUG: 4372: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:42,689 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:42,690 [root] DEBUG: 4372: set_hooks: Unable to hook LockResource
2026-05-28 20:03:42,712 [root] DEBUG: 4372: Hooked 627 out of 628 functions
2026-05-28 20:03:42,743 [root] INFO: Loaded monitor into process with pid 4372
2026-05-28 20:03:42,746 [root] DEBUG: Error 317 (0x13d) - InjectDllViaThread: RtlCreateUserThread injection failed: The system cannot find message text for message number 0x%1 in the message file for %2.
2026-05-28 20:03:42,746 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:43,776 [root] INFO: Restarting WMI Service
2026-05-28 20:03:44,829 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFA80000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:03:44,830 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFA80000: C:\Windows\system32\DUI70 (0x1ae000 bytes).
2026-05-28 20:03:44,836 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5A20000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:03:44,837 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5A20000: C:\Windows\system32\DUser (0x95000 bytes).
2026-05-28 20:03:44,919 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:03:44,920 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFF70000: C:\Windows\SYSTEM32\MsftEdit (0x34d000 bytes).
2026-05-28 20:03:44,928 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:03:44,929 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE41B0000: C:\Windows\SYSTEM32\globinputhost (0x25000 bytes).
2026-05-28 20:03:44,943 [root] DEBUG: 4372: DLL loaded at 0x00007FFED99D0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:03:44,944 [root] DEBUG: 4372: DLL loaded at 0x00007FFED99D0000: C:\Program Files\Common Files\microsoft shared\ink\tiptsf (0xa9000 bytes).
2026-05-28 20:03:44,989 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE6100000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:03:44,990 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE6100000: C:\Windows\System32\Windows.Internal.System.UserProfile (0x43000 bytes).
2026-05-28 20:03:44,995 [root] DEBUG: 4372: DLL loaded at 0x0000000013FF0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:03:44,997 [root] DEBUG: 4372: DLL loaded at 0x0000000013FF0000: C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.3636_none_91a19322cc8a92a3\gdiplus (0x1a5000 bytes).
2026-05-28 20:03:44,997 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8C50000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:03:44,998 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8C50000: C:\Windows\system32\UIRibbon (0x3ec000 bytes).
2026-05-28 20:03:45,338 [lib.api.process] INFO: Monitor config for process 848: C:\6lreqs2g\dll\848.ini
2026-05-28 20:03:45,340 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:45,340 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:45,344 [root] DEBUG: Loader: Injecting process 848 with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:45,346 [root] DEBUG: 848: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:45,347 [root] DEBUG: 848: Disabling sleep skipping.
2026-05-28 20:03:45,347 [root] DEBUG: 848: Interactive desktop enabled.
2026-05-28 20:03:45,348 [root] DEBUG: 848: Dropped file limit defaulting to 100.
2026-05-28 20:03:45,349 [root] DEBUG: 848: Services hook set enabled
2026-05-28 20:03:45,351 [root] DEBUG: 848: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:45,362 [root] DEBUG: 848: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:45,363 [root] DEBUG: 848: Monitor initialised: 64-bit capemon loaded in process 848 at 0x00007FFEAF1A0000, thread 5992, image base 0x00007FF6A8D80000, stack from 0x0000006A4CBF4000-0x0000006A4CC00000
2026-05-28 20:03:45,364 [root] DEBUG: 848: Commandline: C:\Windows\system32\svchost.exe -k DcomLaunch -p
2026-05-28 20:03:45,375 [root] DEBUG: 848: Hooked 69 out of 69 functions
2026-05-28 20:03:45,376 [root] INFO: Loaded monitor into process with pid 848
2026-05-28 20:03:45,376 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:03:45,377 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:45,379 [lib.api.process] INFO: Injected into 64-bit <Process 848 svchost.exe>
2026-05-28 20:03:45,816 [root] DEBUG: package modules.packages.ps1 does not support configure, ignoring
2026-05-28 20:03:45,821 [root] WARNING: configuration error for package modules.packages.ps1: error importing data.packages.ps1: No module named 'data.packages'
2026-05-28 20:03:45,824 [lib.core.compound] INFO: C:\Users\admin\AppData\Local\Temp already exists, skipping creation
2026-05-28 20:03:45,832 [lib.api.process] INFO: Successfully executed process from path "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" with arguments "-NoProfile -ExecutionPolicy bypass -File "C:\Users\admin\AppData\Local\Temp\test-serial.ps1"" with pid 7096
2026-05-28 20:03:45,836 [lib.api.process] INFO: Monitor config for process 7096: C:\6lreqs2g\dll\7096.ini
2026-05-28 20:03:45,840 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:46,557 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:46,561 [root] DEBUG: Loader: Injecting process 7096 (thread 784) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:46,562 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:46,562 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:46,564 [lib.api.process] INFO: Injected into 64-bit <Process 7096 powershell.exe>
2026-05-28 20:03:47,533 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:03:47,534 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4610000: C:\Windows\System32\Windows.Services.TargetedContent (0x123000 bytes).
2026-05-28 20:03:47,600 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:47,601 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6220, handle 0x1b44: Error obtaining target process name
2026-05-28 20:03:47,602 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:47,607 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 8780, handle 0x2600: Error obtaining target process name
2026-05-28 20:03:47,609 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:47,610 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6028, handle 0x2654: Error obtaining target process name
2026-05-28 20:03:47,610 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:47,611 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 6632, handle 0x1b38: Error obtaining target process name
2026-05-28 20:03:47,611 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:47,612 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7448, handle 0x1b60: Error obtaining target process name
2026-05-28 20:03:47,658 [root] DEBUG: 4372: api-rate-cap: IsDebuggerPresent hook disabled due to rate
2026-05-28 20:03:47,714 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
2026-05-28 20:03:47,726 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8610000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:03:47,727 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8610000: C:\Windows\system32\NetworkExplorer (0x17000 bytes).
2026-05-28 20:03:47,753 [root] DEBUG: 4372: api-rate-cap: NtClose hook disabled due to rate
2026-05-28 20:03:47,802 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4800000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 20:03:47,803 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4800000: C:\Windows\System32\windows.internal.shell.broker (0xdd000 bytes).
2026-05-28 20:03:47,815 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:03:47,816 [root] DEBUG: 4372: DLL loaded at 0x00007FFED8180000: C:\Windows\system32\WINMM (0x27000 bytes).
2026-05-28 20:03:47,941 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 1824: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:03:47,942 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1824
2026-05-28 20:03:47,943 [lib.api.process] INFO: Monitor config for process 1824: C:\6lreqs2g\dll\1824.ini
2026-05-28 20:03:47,943 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:47,945 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:47,949 [root] DEBUG: Loader: Injecting process 1824 (thread 2040) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:47,950 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:47,950 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:47,953 [lib.api.process] INFO: Injected into 64-bit <Process 1824 dllhost.exe>
2026-05-28 20:03:47,953 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 1824
2026-05-28 20:03:47,954 [lib.api.process] INFO: Monitor config for process 1824: C:\6lreqs2g\dll\1824.ini
2026-05-28 20:03:47,954 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:47,955 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:47,962 [root] DEBUG: Loader: Injecting process 1824 (thread 2040) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:47,965 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:47,966 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:47,968 [lib.api.process] INFO: Injected into 64-bit <Process 1824 dllhost.exe>
2026-05-28 20:03:47,973 [root] DEBUG: 1824: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:47,973 [root] DEBUG: 1824: Interactive desktop enabled.
2026-05-28 20:03:47,974 [root] DEBUG: 1824: Dropped file limit defaulting to 100.
2026-05-28 20:03:47,975 [root] DEBUG: 1824: Disabling sleep skipping.
2026-05-28 20:03:47,977 [root] DEBUG: 1824: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:47,991 [root] DEBUG: 1824: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:47,994 [root] DEBUG: 1824: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:03:47,995 [root] DEBUG: 1824: Monitor initialised: 64-bit capemon loaded in process 1824 at 0x00007FFEAF1A0000, thread 2040, image base 0x00007FF6868D0000, stack from 0x00000017A6374000-0x00000017A6380000
2026-05-28 20:03:47,996 [root] DEBUG: 1824: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:03:48,005 [root] DEBUG: 1824: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:48,028 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:48,030 [root] DEBUG: 1824: set_hooks: Unable to hook LockResource
2026-05-28 20:03:48,035 [root] DEBUG: 1824: Hooked 627 out of 628 functions
2026-05-28 20:03:48,036 [root] DEBUG: 1824: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:48,041 [root] DEBUG: 1824: RestoreHeaders: Restored original import table.
2026-05-28 20:03:48,042 [root] INFO: Loaded monitor into process with pid 1824
2026-05-28 20:03:48,043 [root] DEBUG: 1824: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 2040).
2026-05-28 20:03:48,043 [root] DEBUG: 1824: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:03:48,044 [root] DEBUG: 1824: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:48,046 [root] DEBUG: 1824: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:03:48,047 [root] DEBUG: 1824: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:03:48,050 [root] DEBUG: 1824: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:03:48,063 [root] DEBUG: 1824: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:03:48,078 [root] DEBUG: 1824: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:03:48,078 [root] DEBUG: 1824: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:03:48,084 [root] DEBUG: 1824: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:03:48,566 [lib.api.process] INFO: Successfully resumed process with pid 7096
2026-05-28 20:03:48,639 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 9588, handle 0x2964: C:\Windows\System32\conhost.exe
2026-05-28 20:03:48,652 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 9588 (handle 0x2aac): 0x00007FF66D090000.
2026-05-28 20:03:48,662 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 7096, handle 0x29b8: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
2026-05-28 20:03:48,666 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 7096 (handle 0x2a8c): 0x00007FF64F320000.
2026-05-28 20:03:48,686 [root] DEBUG: 7096: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:48,687 [root] DEBUG: 7096: Interactive desktop enabled.
2026-05-28 20:03:48,688 [root] DEBUG: 7096: Dropped file limit defaulting to 100.
2026-05-28 20:03:48,690 [root] DEBUG: 4372: api-rate-cap: GetSystemMetrics hook disabled due to rate
2026-05-28 20:03:48,690 [root] DEBUG: 7096: Disabling sleep skipping.
2026-05-28 20:03:48,692 [root] DEBUG: 7096: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:48,704 [root] DEBUG: 7096: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:48,705 [root] DEBUG: 4372: api-rate-cap: SystemParametersInfoW hook disabled due to rate
2026-05-28 20:03:48,705 [root] DEBUG: 7096: YaraScan: Scanning 0x00007FF64F320000, size 0x7caba
2026-05-28 20:03:48,709 [root] DEBUG: 7096: Monitor initialised: 64-bit capemon loaded in process 7096 at 0x00007FFEAF1A0000, thread 784, image base 0x00007FF64F320000, stack from 0x000000045AEE4000-0x000000045AEF0000
2026-05-28 20:03:48,710 [root] DEBUG: 7096: Commandline: "C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -ExecutionPolicy bypass -File "C:\Users\admin\AppData\Local\Temp\test-serial.ps1"
2026-05-28 20:03:48,720 [root] DEBUG: 7096: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:48,743 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:48,744 [root] DEBUG: 7096: set_hooks: Unable to hook LockResource
2026-05-28 20:03:48,748 [root] DEBUG: 7096: Hooked 627 out of 628 functions
2026-05-28 20:03:48,751 [root] DEBUG: 7096: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:48,756 [root] DEBUG: 7096: RestoreHeaders: Restored original import table.
2026-05-28 20:03:48,756 [root] INFO: Loaded monitor into process with pid 7096
2026-05-28 20:03:48,768 [root] DEBUG: 7096: caller_dispatch: Added region at 0x00007FF64F320000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF64F324D21, thread 784).
2026-05-28 20:03:48,769 [root] DEBUG: 7096: YaraScan: Scanning 0x00007FF64F320000, size 0x7caba
2026-05-28 20:03:48,772 [root] DEBUG: 7096: ProcessImageBase: Main module image at 0x00007FF64F320000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:48,777 [root] DEBUG: 7096: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:03:48,779 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:03:48,782 [root] DEBUG: 7096: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:03:48,784 [root] DEBUG: 7096: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:03:48,788 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF080000: C:\Windows\system32\Wldp (0x2d000 bytes).
2026-05-28 20:03:48,789 [root] DEBUG: 7096: DLL loaded at 0x00007FFEED7F0000: C:\Windows\system32\windows.storage (0x79b000 bytes).
2026-05-28 20:03:48,793 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE4250000: C:\Windows\System32\Bcp47Langs (0x5b000 bytes).
2026-05-28 20:03:48,797 [root] DEBUG: 7096: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:03:48,798 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEE220000: C:\Windows\System32\sppc (0x25000 bytes).
2026-05-28 20:03:48,798 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEE250000: C:\Windows\System32\SLC (0x29000 bytes).
2026-05-28 20:03:48,798 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\System32\USERENV (0x2e000 bytes).
2026-05-28 20:03:48,799 [root] DEBUG: 7096: DLL loaded at 0x00007FFEDDAE0000: C:\Windows\System32\appresolver (0x90000 bytes).
2026-05-28 20:03:48,805 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:03:48,817 [root] DEBUG: 7096: DLL loaded at 0x00007FFED7420000: C:\Windows\SYSTEM32\LINKINFO (0xd000 bytes).
2026-05-28 20:03:48,833 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:03:48,895 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF710000: C:\Windows\System32\CFGMGR32 (0x4e000 bytes).
2026-05-28 20:03:48,988 [root] DEBUG: 7096: api-rate-cap: RegQueryValueExW hook disabled due to rate
2026-05-28 20:03:49,015 [root] DEBUG: 7096: api-rate-cap: NtQueryValueKey hook disabled due to rate
2026-05-28 20:03:49,059 [root] DEBUG: 7096: DLL loaded at 0x00007FFED77F0000: C:\Windows\SYSTEM32\ntshrui (0x7d000 bytes).
2026-05-28 20:03:49,061 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE61A0000: C:\Windows\SYSTEM32\srvcli (0x28000 bytes).
2026-05-28 20:03:49,063 [root] DEBUG: 7096: DLL loaded at 0x00007FFEDCD00000: C:\Windows\SYSTEM32\cscapi (0x12000 bytes).
2026-05-28 20:03:49,077 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEE7A0000: C:\Windows\system32\msvcp110_win (0x8a000 bytes).
2026-05-28 20:03:49,078 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEA450000: C:\Windows\SYSTEM32\policymanager (0xa1000 bytes).
2026-05-28 20:03:49,108 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0J6PCFR9ND41B9TD7TBV.temp
2026-05-28 20:03:49,116 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:03:49,117 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
2026-05-28 20:03:49,125 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF1270b.TMP to files\e53c99aa9e7490e86a1cd3a772779748b2f0e8317c480840381b01cd4d8dd7b2; Size is 5441; Max size: 100000000
2026-05-28 20:03:49,134 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEB550000: C:\Windows\SYSTEM32\wintypes (0x155000 bytes).
2026-05-28 20:03:49,134 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF550000: C:\Windows\System32\UMPDC (0x12000 bytes).
2026-05-28 20:03:49,138 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\cryptsp (0x18000 bytes).
2026-05-28 20:03:49,139 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEB400000: C:\Windows\System32\dsreg (0x141000 bytes).
2026-05-28 20:03:49,139 [root] DEBUG: 7096: DLL loaded at 0x00007FFEDE340000: C:\Windows\System32\cdp (0x4d4000 bytes).
2026-05-28 20:03:49,140 [root] DEBUG: 7096: DLL loaded at 0x00007FFED6EF0000: C:\Windows\System32\TaskFlowDataEngine (0x17e000 bytes).
2026-05-28 20:03:49,146 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:03:49,155 [root] DEBUG: Error 5 (0x5) - OpenProcessHandler: Error obtaining target process name: Access is denied.
2026-05-28 20:03:49,155 [root] DEBUG: 7096: OpenProcessHandler: Injection info created for process 4372, handle 0x420: Error obtaining target process name
2026-05-28 20:03:49,162 [root] DEBUG: 7096: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-05-28 20:03:49,168 [root] DEBUG: 7096: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-05-28 20:03:49,172 [root] DEBUG: 7096: DLL loaded at 0x00007FFED9910000: C:\Windows\SYSTEM32\ucrtbase_clr0400 (0xbd000 bytes).
2026-05-28 20:03:49,173 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE8480000: C:\Windows\SYSTEM32\VCRUNTIME140_CLR0400 (0x16000 bytes).
2026-05-28 20:03:49,174 [root] DEBUG: 7096: DLL loaded at 0x000001C41A660000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb34000 bytes).
2026-05-28 20:03:49,248 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C3BB220000, size: 0x1000.
2026-05-28 20:03:49,263 [root] DEBUG: 7096: hook_api: clrjit::compileMethod export address 0x00007FFEAE515FF0 obtained via GetFunctionAddress
2026-05-28 20:03:49,265 [root] DEBUG: 7096: DLL loaded at 0x00007FFEAE510000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clrjit (0x14f000 bytes).
2026-05-28 20:03:49,279 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB220000: scans and dumps active.
2026-05-28 20:03:49,281 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x00007DF467C40000, size: 0xa0000.
2026-05-28 20:03:49,281 [root] DEBUG: 7096: GetEntropy: Error - Supplied address inaccessible: 0x00007DF467C40000
2026-05-28 20:03:49,282 [root] DEBUG: 7096: AllocationHandler: Processing previous tracked region at: 0x000001C3BB220000.
2026-05-28 20:03:49,282 [root] DEBUG: 7096: ProcessTrackedRegion: Entropy for tracked region at 0x000001C3BB220000: 5.773624e+00
2026-05-28 20:03:49,282 [root] DEBUG: 7096: DumpPEsInRange: Scanning range 0x000001C3BB220000 - 0x000001C3BB227409.
2026-05-28 20:03:49,283 [root] DEBUG: 7096: ScanForDisguisedPE: No PE image located in range 0x000001C3BB220000-0x000001C3BB227409.
2026-05-28 20:03:49,284 [lib.common.results] INFO: Uploading file C:\JzexnPnz\CAPE\7096_3487047493029552026 to CAPE\803db83a2ffe17a2b204b72b3715eda7e41d36aeb47261abdbe5ec760149dbe9; Size is 29705; Max size: 100000000
2026-05-28 20:03:49,286 [root] DEBUG: 7096: DumpMemory: Payload successfully created: C:\JzexnPnz\CAPE\7096_3487047493029552026 (size 29705 bytes)
2026-05-28 20:03:49,287 [root] DEBUG: 7096: DumpRegion: Dumped entire allocation from 0x000001C3BB220000, size 32768 bytes.
2026-05-28 20:03:49,288 [root] DEBUG: 7096: ProcessTrackedRegion: Dumped region at 0x000001C3BB220000.
2026-05-28 20:03:49,288 [root] DEBUG: 7096: YaraScan: Scanning 0x000001C3BB220000, size 0x7409
2026-05-28 20:03:49,290 [root] DEBUG: 7096: AllocationHandler: Memory region (size 0xa0000) reserved but not committed at 0x00007DF467C40000.
2026-05-28 20:03:49,290 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x00007DF467C40000, committing at: 0x00007DF467C40000.
2026-05-28 20:03:49,291 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x00007DF467C30000, size: 0x10000.
2026-05-28 20:03:49,291 [root] DEBUG: 7096: GetEntropy: Error - Supplied address inaccessible: 0x00007DF467C30000
2026-05-28 20:03:49,292 [root] DEBUG: 7096: AllocationHandler: Processing previous tracked region at: 0x00007DF467C40000.
2026-05-28 20:03:49,292 [root] DEBUG: 7096: ProcessTrackedRegion: Entropy for tracked region at 0x00007DF467C40000: 1.749543e-01
2026-05-28 20:03:49,293 [root] DEBUG: 7096: DumpPEsInRange: Scanning range 0x00007DF467C40000 - 0x00007DF467C40066.
2026-05-28 20:03:49,293 [root] DEBUG: 7096: ScanForDisguisedPE: Size too small: 0x66 bytes
2026-05-28 20:03:49,295 [lib.common.results] INFO: Uploading file C:\JzexnPnz\CAPE\7096_8104830493029552026 to CAPE\c767d3d52d03d9fdd7301e4d33c937e13fa6828c2bd214150a483fd25b4985fd; Size is 102; Max size: 100000000
2026-05-28 20:03:49,297 [root] DEBUG: 7096: DumpMemory: Payload successfully created: C:\JzexnPnz\CAPE\7096_8104830493029552026 (size 102 bytes)
2026-05-28 20:03:49,297 [root] DEBUG: 7096: DumpRegion: Dumped entire allocation from 0x00007DF467C40000, size 4096 bytes.
2026-05-28 20:03:49,297 [root] DEBUG: 7096: ProcessTrackedRegion: Dumped region at 0x00007DF467C40000.
2026-05-28 20:03:49,298 [root] DEBUG: 7096: YaraScan: Scanning 0x00007DF467C40000, size 0x66
2026-05-28 20:03:49,298 [root] DEBUG: 7096: AllocationHandler: Memory region (size 0x10000) reserved but not committed at 0x00007DF467C30000.
2026-05-28 20:03:49,299 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x00007DF467C30000, committing at: 0x00007DF467C30000.
2026-05-28 20:03:49,299 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C3BB05D000, size: 0x1000.
2026-05-28 20:03:49,331 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C4334E2000, size: 0x1000.
2026-05-28 20:03:49,332 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB220000.
2026-05-28 20:03:49,359 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB220000.
2026-05-28 20:03:49,360 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB220000.
2026-05-28 20:03:49,361 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB220000.
2026-05-28 20:03:49,372 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:03:49,462 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C3BB136000, size: 0x1000.
2026-05-28 20:03:49,745 [root] DEBUG: 7096: api-rate-cap: NtDelayExecution hook disabled due to rate
2026-05-28 20:03:49,768 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB510000: scans and dumps active.
2026-05-28 20:03:49,779 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BB510000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x000001C3BB514653, thread 10176).
2026-05-28 20:03:49,780 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BB510000 skipped
2026-05-28 20:03:50,142 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB050000.
2026-05-28 20:03:50,182 [root] DEBUG: 7096: DLL loaded at 0x00007FFEF0240000: C:\Windows\System32\psapi (0x8000 bytes).
2026-05-28 20:03:50,237 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB050000.
2026-05-28 20:03:50,276 [root] DEBUG: 7096: DLL loaded at 0x00007FFEF0020000: C:\Windows\System32\wintrust (0x67000 bytes).
2026-05-28 20:03:50,277 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEF210000: C:\Windows\SYSTEM32\MSASN1 (0x12000 bytes).
2026-05-28 20:03:50,283 [root] DEBUG: 7096: DLL loaded at 0x00007FFED90A0000: C:\Windows\SYSTEM32\amsi (0x1f000 bytes).
2026-05-28 20:03:50,290 [root] DEBUG: 7096: DLL loaded at 0x00007FFED9050000: C:\Program Files\Windows Defender\MpOav (0x44000 bytes).
2026-05-28 20:03:50,300 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEDFA0000: C:\Windows\SYSTEM32\gpapi (0x23000 bytes).
2026-05-28 20:03:50,327 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_n3m4ctbf.bg0.ps1
2026-05-28 20:03:50,329 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ak50klju.lzo.psm1
2026-05-28 20:03:50,337 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE5880000: C:\Windows\System32\MSISIP (0x15000 bytes).
2026-05-28 20:03:50,338 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE5860000: C:\Windows\System32\wshext (0x1e000 bytes).
2026-05-28 20:03:50,340 [root] DEBUG: 7096: DLL loaded at 0x00007FFED9290000: C:\Windows\SYSTEM32\OpcServices (0x21d000 bytes).
2026-05-28 20:03:50,340 [root] DEBUG: 7096: DLL loaded at 0x00007FFEDFA30000: C:\Windows\System32\AppxSip (0x4c000 bytes).
2026-05-28 20:03:50,342 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C3BB6C0000, size: 0x1000.
2026-05-28 20:03:50,344 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE8980000: C:\Windows\System32\WindowsPowerShell\v1.0\pwrshsip (0xc000 bytes).
2026-05-28 20:03:50,349 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB6D0000: scans and dumps active.
2026-05-28 20:03:50,349 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB6D0000: scans and dumps active.
2026-05-28 20:03:50,350 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BB6D0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x000001C3BB6D05BE, thread 784).
2026-05-28 20:03:50,351 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BB6D0000 skipped
2026-05-28 20:03:50,352 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_n3m4ctbf.bg0.ps1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 20:03:50,363 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x000001C3BB6D0000, committing at: 0x000001C3BB6D4000.
2026-05-28 20:03:50,365 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ak50klju.lzo.psm1 to files\96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7; Size is 60; Max size: 100000000
2026-05-28 20:03:50,388 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:50,391 [root] DEBUG: 7096: DLL loaded at 0x00007FFEAE1A0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data (0x36c000 bytes).
2026-05-28 20:03:50,459 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:50,639 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB890000: scans and dumps active.
2026-05-28 20:03:50,651 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BB890000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x000001C3BB893F0C, thread 784).
2026-05-28 20:03:50,652 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BB890000 skipped
2026-05-28 20:03:50,658 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C4334E0000.
2026-05-28 20:03:50,658 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C4334E0000.
2026-05-28 20:03:50,659 [root] DEBUG: 7096: AllocationHandler: Adding allocation to tracked region list: 0x000001C4344F0000, size: 0x32000.
2026-05-28 20:03:50,660 [root] DEBUG: 7096: GetEntropy: Error - Supplied address inaccessible: 0x000001C4344F0000
2026-05-28 20:03:50,660 [root] DEBUG: 7096: AllocationHandler: Memory region (size 0x32000) reserved but not committed at 0x000001C4344F0000.
2026-05-28 20:03:50,662 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x000001C4344F0000, committing at: 0x000001C4344F0000.
2026-05-28 20:03:50,693 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x000001C3BB890000, committing at: 0x000001C3BB8A3000.
2026-05-28 20:03:50,727 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:50,783 [root] DEBUG: 7096: api-rate-cap: ReadProcessMemory hook disabled due to rate
2026-05-28 20:03:50,798 [root] DEBUG: 7096: api-rate-cap: NtReadVirtualMemory hook disabled due to rate
2026-05-28 20:03:50,878 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BB9F0000: scans and dumps active.
2026-05-28 20:03:50,881 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BB9F0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x000001C3BB9F0BC2, thread 784).
2026-05-28 20:03:50,881 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BB9F0000 skipped
2026-05-28 20:03:50,942 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:50,943 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x000001C3BB9F0000, committing at: 0x000001C3BBA04000.
2026-05-28 20:03:50,957 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB6C0000.
2026-05-28 20:03:51,033 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BBAC0000: scans and dumps active.
2026-05-28 20:03:51,069 [root] DEBUG: 7096: DLL loaded at 0x00007FFED98C0000: C:\Windows\Microsoft.Net\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions (0x4f000 bytes).
2026-05-28 20:03:51,097 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:51,113 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:51,133 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:51,143 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE0DA0000: C:\Windows\SYSTEM32\secur32 (0xc000 bytes).
2026-05-28 20:03:51,153 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BBB80000: scans and dumps active.
2026-05-28 20:03:51,154 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BBB80000: scans and dumps active.
2026-05-28 20:03:51,154 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BBB80000: scans and dumps active.
2026-05-28 20:03:51,155 [root] DEBUG: 7096: .NET JIT native cache at 0x000001C3BBB80000: scans and dumps active.
2026-05-28 20:03:51,157 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BBB80000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x000001C3BBB81922, thread 10176).
2026-05-28 20:03:51,158 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BBB80000 skipped
2026-05-28 20:03:51,166 [root] DEBUG: 7096: AllocationHandler: Previously reserved region at 0x000001C3BBB80000, committing at: 0x000001C3BBB88000.
2026-05-28 20:03:51,202 [root] DEBUG: 7096: AllocationHandler: Allocation already in tracked region list: 0x000001C3BB100000.
2026-05-28 20:03:51,268 [root] DEBUG: 7096: api-rate-cap: NtAllocateVirtualMemory hook disabled due to rate
2026-05-28 20:03:51,292 [root] DEBUG: 7096: api-cap: compileMethod hook disabled due to count: 5000
2026-05-28 20:03:51,293 [root] DEBUG: 7096: api-cap: compileMethod hook disabled due to count: 5001
2026-05-28 20:03:51,342 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BBDB0000 to tracked regions list (ntdll::NtFreeVirtualMemory returns to 0x000001C3BBDB055E, thread 784).
2026-05-28 20:03:51,343 [root] DEBUG: 7096: ProcessTrackedRegion: Updated entropy for tracked region at 0x000001C3BBDB0000: 4.210999e+00 (from 4.065946e+00)
2026-05-28 20:03:51,344 [root] DEBUG: 7096: DumpPEsInRange: Scanning range 0x000001C3BBDB0000 - 0x000001C3BBDB17C5.
2026-05-28 20:03:51,344 [root] DEBUG: 7096: ScanForDisguisedPE: No PE image located in range 0x000001C3BBDB0000-0x000001C3BBDB17C5.
2026-05-28 20:03:51,345 [lib.common.results] INFO: Uploading file C:\JzexnPnz\CAPE\7096_4254248513029552026 to CAPE\592395040c58693bee80a2a4bb7958951c734cb1ca2a3e77104c5309fb42cd5f; Size is 6085; Max size: 100000000
2026-05-28 20:03:51,348 [root] DEBUG: 7096: DumpMemory: Payload successfully created: C:\JzexnPnz\CAPE\7096_4254248513029552026 (size 6085 bytes)
2026-05-28 20:03:51,349 [root] DEBUG: 7096: DumpRegion: Dumped entire allocation from 0x000001C3BBDB0000, size 8192 bytes.
2026-05-28 20:03:51,349 [root] DEBUG: 7096: ProcessTrackedRegion: Dumped region at 0x000001C3BBDB0000.
2026-05-28 20:03:51,525 [root] DEBUG: 7096: DLL loaded at 0x00007FFEE3EC0000: C:\Program Files\Windows Defender\MPCLIENT (0xe9000 bytes).
2026-05-28 20:03:51,782 [root] DEBUG: 7096: api-rate-cap: NtFreeVirtualMemory hook disabled due to rate
2026-05-28 20:03:51,783 [root] DEBUG: 7096: api-rate-cap: NtFreeVirtualMemory hook disabled due to rate
2026-05-28 20:03:52,005 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.tmp
2026-05-28 20:03:52,007 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.0.cs
2026-05-28 20:03:52,011 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.dll
2026-05-28 20:03:52,016 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.cmdline
2026-05-28 20:03:52,039 [root] DEBUG: 7096: CreateProcessHandler: Injection info set for new process 10500: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe, ImageBase: 0x00007FF6A4C60000
2026-05-28 20:03:52,040 [root] INFO: Announced 64-bit process name: csc.exe pid: 10500
2026-05-28 20:03:52,041 [lib.api.process] INFO: Monitor config for process 10500: C:\6lreqs2g\dll\10500.ini
2026-05-28 20:03:52,041 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:52,135 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:52,139 [root] DEBUG: Loader: Injecting process 10500 (thread 10504) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,140 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:52,141 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,142 [lib.api.process] INFO: Injected into 64-bit <Process 10500 csc.exe>
2026-05-28 20:03:52,144 [root] INFO: Announced 64-bit process name: csc.exe pid: 10500
2026-05-28 20:03:52,144 [lib.api.process] INFO: Monitor config for process 10500: C:\6lreqs2g\dll\10500.ini
2026-05-28 20:03:52,145 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:52,214 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:52,218 [root] DEBUG: Loader: Injecting process 10500 (thread 10504) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,219 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:52,219 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,220 [lib.api.process] INFO: Injected into 64-bit <Process 10500 csc.exe>
2026-05-28 20:03:52,221 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.out
2026-05-28 20:03:52,222 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.err
2026-05-28 20:03:52,227 [root] DEBUG: 10500: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:52,227 [root] DEBUG: 10500: Interactive desktop enabled.
2026-05-28 20:03:52,227 [root] DEBUG: 10500: Dropped file limit defaulting to 100.
2026-05-28 20:03:52,229 [root] DEBUG: 10500: Disabling sleep skipping.
2026-05-28 20:03:52,230 [root] DEBUG: 10500: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:52,242 [root] DEBUG: 10500: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:52,242 [root] DEBUG: 10500: YaraScan: Scanning 0x00007FF6A4C60000, size 0x2a631c
2026-05-28 20:03:52,272 [root] DEBUG: 10500: Monitor initialised: 64-bit capemon loaded in process 10500 at 0x00007FFEAF1A0000, thread 10504, image base 0x00007FF6A4C60000, stack from 0x000000FFF99F4000-0x000000FFF9A00000
2026-05-28 20:03:52,273 [root] DEBUG: 10500: Commandline: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.cmdline"
2026-05-28 20:03:52,282 [root] DEBUG: 10500: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:52,302 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:52,303 [root] DEBUG: 10500: set_hooks: Unable to hook LockResource
2026-05-28 20:03:52,307 [root] DEBUG: 10500: Hooked 627 out of 628 functions
2026-05-28 20:03:52,323 [root] DEBUG: 10500: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:52,327 [root] DEBUG: 10500: RestoreHeaders: Restored original import table.
2026-05-28 20:03:52,327 [root] INFO: Loaded monitor into process with pid 10500
2026-05-28 20:03:52,332 [root] DEBUG: 10500: caller_dispatch: Added region at 0x00007FF6A4C60000 to tracked regions list (ntdll::LdrGetDllHandle returns to 0x00007FF6A4E51120, thread 10504).
2026-05-28 20:03:52,333 [root] DEBUG: 10500: YaraScan: Scanning 0x00007FF6A4C60000, size 0x2a631c
2026-05-28 20:03:52,349 [root] DEBUG: 10500: ProcessImageBase: Main module image at 0x00007FF6A4C60000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:52,356 [root] DEBUG: 10500: DLL loaded at 0x00007FFED9040000: C:\Windows\SYSTEM32\VERSION (0xa000 bytes).
2026-05-28 20:03:52,358 [root] DEBUG: 10500: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:03:52,359 [root] DEBUG: 10500: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:03:52,364 [root] DEBUG: 10500: DLL loaded at 0x00007FFEF1ED0000: C:\Windows\System32\imagehlp (0x1d000 bytes).
2026-05-28 20:03:52,365 [root] DEBUG: 10500: DLL loaded at 0x00007FFED9890000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\alink (0x2e000 bytes).
2026-05-28 20:03:52,367 [root] DEBUG: 10500: DLL loaded at 0x00007FFEE59B0000: C:\Windows\SYSTEM32\mscoree (0x65000 bytes).
2026-05-28 20:03:52,371 [root] DEBUG: 10500: DLL loaded at 0x00007FFEDFDD0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei (0xaa000 bytes).
2026-05-28 20:03:52,382 [root] DEBUG: 10500: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:03:52,383 [root] DEBUG: 10500: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:03:52,386 [root] DEBUG: 10500: DLL loaded at 0x00000280B26F0000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr (0xb34000 bytes).
2026-05-28 20:03:52,503 [root] DEBUG: 10500: DLL loaded at 0x00007FFED9710000: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorpehost (0x31000 bytes).
2026-05-28 20:03:52,510 [root] INFO: Added new file to list with pid 10500 and path C:\Users\admin\AppData\Local\Temp\hiico0zm\CSCBF7B95ECC7894A45ABC2E9DD2A746E8C.TMP
2026-05-28 20:03:52,514 [root] DEBUG: 10500: DLL loaded at 0x00007FFEEF080000: C:\Windows\SYSTEM32\Wldp (0x2d000 bytes).
2026-05-28 20:03:52,514 [root] DEBUG: 10500: DLL loaded at 0x00007FFEED7F0000: C:\Windows\SYSTEM32\windows.storage (0x79b000 bytes).
2026-05-28 20:03:52,516 [root] DEBUG: 10500: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\SHCORE (0xad000 bytes).
2026-05-28 20:03:52,517 [root] DEBUG: 10500: CreateProcessHandler: Injection info set for new process 10752: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe, ImageBase: 0x00007FF6DCEC0000
2026-05-28 20:03:52,517 [root] INFO: Announced 64-bit process name: cvtres.exe pid: 10752
2026-05-28 20:03:52,517 [lib.api.process] INFO: Monitor config for process 10752: C:\6lreqs2g\dll\10752.ini
2026-05-28 20:03:52,518 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:52,588 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:52,592 [root] DEBUG: Loader: Injecting process 10752 (thread 10756) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,592 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:52,593 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,594 [lib.api.process] INFO: Injected into 64-bit <Process 10752 cvtres.exe>
2026-05-28 20:03:52,599 [root] INFO: Announced 64-bit process name: cvtres.exe pid: 10752
2026-05-28 20:03:52,599 [lib.api.process] INFO: Monitor config for process 10752: C:\6lreqs2g\dll\10752.ini
2026-05-28 20:03:52,599 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:52,673 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:52,677 [root] DEBUG: Loader: Injecting process 10752 (thread 10756) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,677 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:03:52,678 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:52,679 [lib.api.process] INFO: Injected into 64-bit <Process 10752 cvtres.exe>
2026-05-28 20:03:52,686 [root] DEBUG: 10752: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:52,687 [root] DEBUG: 10752: Interactive desktop enabled.
2026-05-28 20:03:52,687 [root] DEBUG: 10752: Dropped file limit defaulting to 100.
2026-05-28 20:03:52,688 [root] DEBUG: 10752: Disabling sleep skipping.
2026-05-28 20:03:52,689 [root] DEBUG: 10752: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:52,703 [root] DEBUG: 10752: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:52,703 [root] DEBUG: 10752: YaraScan: Scanning 0x00007FF6DCEC0000, size 0xd054
2026-05-28 20:03:52,704 [root] DEBUG: 10752: Monitor initialised: 64-bit capemon loaded in process 10752 at 0x00007FFEAF1A0000, thread 10756, image base 0x00007FF6DCEC0000, stack from 0x000000C49C0F4000-0x000000C49C100000
2026-05-28 20:03:52,705 [root] DEBUG: 10752: Commandline: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES3449.tmp" "c:\Users\admin\AppData\Local\Temp\hiico0zm\CSCBF7B95ECC7894A45ABC2E9DD2A746E8C.TMP"
2026-05-28 20:03:52,715 [root] DEBUG: 10752: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:52,734 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:52,734 [root] DEBUG: 10752: set_hooks: Unable to hook LockResource
2026-05-28 20:03:52,738 [root] DEBUG: 10752: Hooked 627 out of 628 functions
2026-05-28 20:03:52,739 [root] DEBUG: 10752: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:52,743 [root] DEBUG: 10752: RestoreHeaders: Restored original import table.
2026-05-28 20:03:52,743 [root] INFO: Loaded monitor into process with pid 10752
2026-05-28 20:03:52,746 [root] DEBUG: 10752: caller_dispatch: Added region at 0x00007FF6DCEC0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6DCEC4F10, thread 10756).
2026-05-28 20:03:52,747 [root] DEBUG: 10752: YaraScan: Scanning 0x00007FF6DCEC0000, size 0xd054
2026-05-28 20:03:52,748 [root] DEBUG: 10752: ProcessImageBase: Main module image at 0x00007FF6DCEC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:52,753 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEEFD0000: C:\Windows\SYSTEM32\CRYPTSP (0x18000 bytes).
2026-05-28 20:03:52,753 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEE710000: C:\Windows\system32\rsaenh (0x34000 bytes).
2026-05-28 20:03:52,754 [root] DEBUG: 10752: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:03:52,783 [root] INFO: Added new file to list with pid 10752 and path C:\Users\admin\AppData\Local\Temp\RES3449.tmp
2026-05-28 20:03:52,784 [root] DEBUG: 10752: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:03:52,784 [root] DEBUG: 10752: NtTerminateProcess hook: Attempting to dump process 10752
2026-05-28 20:03:52,786 [root] DEBUG: 10752: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:03:52,803 [root] INFO: Process with pid 10752 has terminated
2026-05-28 20:03:52,807 [root] INFO: Added pid 10500 for C:\Users\admin\AppData\Local\Temp\RES3449.tmp
2026-05-28 20:03:52,807 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\RES3449.tmp to files\52a979cc883bd47b0e77b2455595547619e74372bc4b4a436093da609f9d630a; Size is 1340; Max size: 100000000
2026-05-28 20:03:52,857 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\hiico0zm\CSCBF7B95ECC7894A45ABC2E9DD2A746E8C.TMP to files\d666508709b1410d89a85b574e2e7392fe8bd3976d372fb0da4d4989dc8e4290; Size is 652; Max size: 100000000
2026-05-28 20:03:52,862 [root] DEBUG: 10500: NtTerminateProcess hook: Attempting to dump process 10500
2026-05-28 20:03:52,865 [root] DEBUG: 10500: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:03:52,874 [root] INFO: Process with pid 10500 has terminated
2026-05-28 20:03:52,911 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.0.cs to files\847a3e1877a67b9d3a971aa1c642472975d8a067096ee7b1bfb3bfd143f73a70; Size is 1431; Max size: 100000000
2026-05-28 20:03:52,918 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.dll to files\480a3c0bd1f414b55f9d3e3adaae96fe2a76b0eb2407ffc6cec57cd630d23d54; Size is 4096; Max size: 100000000
2026-05-28 20:03:52,926 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.out to files\6794fea65bf5ab6c69ac9cfb6f8c52b8719e4d1f16388f1187f70a3953ceb110; Size is 880; Max size: 100000000
2026-05-28 20:03:52,929 [lib.common.results] INFO: Uploading file C:\Users\admin\AppData\Local\Temp\hiico0zm\hiico0zm.cmdline to files\f7541971acce1073b918ca1d74fe837958d34769ad22f3cb787cea006f7716f3; Size is 369; Max size: 100000000
2026-05-28 20:03:53,090 [root] DEBUG: 7096: caller_dispatch: Added region at 0x000001C3BBAC0000 to tracked regions list (ntdll::LdrGetProcedureAddressForCaller returns to 0x000001C3BBAC1336, thread 10460).
2026-05-28 20:03:53,092 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BBAC0000 skipped
2026-05-28 20:03:53,163 [root] INFO: Process with pid 1824 has terminated
2026-05-28 20:03:53,164 [root] DEBUG: 1824: NtTerminateProcess hook: Attempting to dump process 1824
2026-05-28 20:03:53,165 [root] DEBUG: 1824: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:03:53,171 [root] INFO: Added new file to list with pid 7096 and path C:\serial_test_results.txt
2026-05-28 20:03:53,214 [root] INFO: Added new file to list with pid 7096 and path C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
2026-05-28 20:03:53,235 [root] DEBUG: 7096: NtTerminateProcess hook: Attempting to dump process 7096
2026-05-28 20:03:53,236 [root] DEBUG: 7096: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:03:53,237 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BB220000 (jit-dumps=0)
2026-05-28 20:03:53,238 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BB510000 (jit-dumps=0)
2026-05-28 20:03:53,238 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BB6D0000 (jit-dumps=0)
2026-05-28 20:03:53,239 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BB890000 (jit-dumps=0)
2026-05-28 20:03:53,240 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BB9F0000 (jit-dumps=0)
2026-05-28 20:03:53,240 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BBAC0000 (jit-dumps=0)
2026-05-28 20:03:53,241 [root] DEBUG: 7096: DumpInterestingRegions: Skipping .NET JIT native cache at 0x000001C3BBB80000 (jit-dumps=0)
2026-05-28 20:03:53,243 [root] DEBUG: 7096: DumpInterestingRegions: Dumping .NET image at 0x000001C41B1C0000.
2026-05-28 20:03:53,244 [root] DEBUG: 7096: DumpImageInCurrentProcess: Attempting to dump virtual PE image.
2026-05-28 20:03:53,244 [root] DEBUG: 7096: DumpProcess: Instantiating PeParser with address: 0x000001C41B1C0000.
2026-05-28 20:03:53,245 [root] DEBUG: 7096: DumpProcess: Module entry point VA is 0x000001C41B1C265E.
2026-05-28 20:03:53,245 [root] DEBUG: 7096: PeParser: End of section 1 RVA 0x4000 is beyond allocated size 0x1000
2026-05-28 20:03:53,246 [root] DEBUG: 7096: PeParser: End of section 2 RVA 0x6000 is beyond allocated size 0x1000
2026-05-28 20:03:53,247 [root] DEBUG: 7096: PeParser: End of section 3 RVA 0x8000 is beyond allocated size 0x1000
2026-05-28 20:03:53,247 [root] DEBUG: 7096: readPeSectionsFromProcess: Failed to relocate image back to header image base 0x0000000010000000.
2026-05-28 20:03:53,256 [root] DEBUG: 7096: DumpProcess: Failed to dump image at 0x000001C41B1C0000.
2026-05-28 20:03:53,257 [root] DEBUG: 7096: DumpImageInCurrentProcess: Failed to dump virtual PE image from 0x000001C41B1C0000, dumping memory region.
2026-05-28 20:03:53,264 [root] DEBUG: 7096: ProcessTrackedRegion: .NET cache region at 0x000001C3BBB80000 skipped
2026-05-28 20:03:53,270 [root] DEBUG: 7096: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\SYSTEM32\netutils (0xc000 bytes).
2026-05-28 20:03:53,274 [root] INFO: Process with pid 7096 has terminated
2026-05-28 20:03:58,220 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:03:58,222 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8A00000: C:\Windows\SYSTEM32\MPR (0x1d000 bytes).
2026-05-28 20:03:58,225 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8980000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:03:58,226 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8980000: C:\Windows\System32\drprov (0xb000 bytes).
2026-05-28 20:03:58,228 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE85F0000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:03:58,229 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE85F0000: C:\Windows\System32\ntlanman (0x1f000 bytes).
2026-05-28 20:03:58,231 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8690000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:03:58,232 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8690000: C:\Windows\System32\DAVHLPR (0xd000 bytes).
2026-05-28 20:03:58,233 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8480000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:03:58,234 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8480000: C:\Windows\System32\davclnt (0x1e000 bytes).
2026-05-28 20:03:58,310 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE59C0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 20:03:58,311 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE59C0000: C:\Windows\System32\dlnashext (0x56000 bytes).
2026-05-28 20:03:58,317 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFE10000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:03:58,317 [root] DEBUG: 4372: DLL loaded at 0x00007FFEDFE10000: C:\Windows\System32\PlayToDevice (0x64000 bytes).
2026-05-28 20:03:58,325 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9920000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 20:03:58,326 [root] DEBUG: 4372: DLL loaded at 0x00007FFED9920000: C:\Windows\system32\wpdshext (0xa1000 bytes).
2026-05-28 20:03:58,339 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5870000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:03:58,341 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE5870000: C:\Windows\System32\EhStorAPI (0x26000 bytes).
2026-05-28 20:03:58,558 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11360: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:03:58,560 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11360
2026-05-28 20:03:58,561 [lib.api.process] INFO: Monitor config for process 11360: C:\6lreqs2g\dll\11360.ini
2026-05-28 20:03:58,563 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:58,569 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:58,574 [root] DEBUG: Loader: Injecting process 11360 (thread 11364) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:58,575 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:58,576 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:58,577 [lib.api.process] INFO: Injected into 64-bit <Process 11360 dllhost.exe>
2026-05-28 20:03:58,578 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11360
2026-05-28 20:03:58,580 [lib.api.process] INFO: Monitor config for process 11360: C:\6lreqs2g\dll\11360.ini
2026-05-28 20:03:58,580 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:03:58,585 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:03:58,590 [root] DEBUG: Loader: Injecting process 11360 (thread 11364) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:58,590 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:03:58,591 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:03:58,594 [lib.api.process] INFO: Injected into 64-bit <Process 11360 dllhost.exe>
2026-05-28 20:03:58,599 [root] DEBUG: 11360: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:03:58,600 [root] DEBUG: 11360: Interactive desktop enabled.
2026-05-28 20:03:58,601 [root] DEBUG: 11360: Dropped file limit defaulting to 100.
2026-05-28 20:03:58,603 [root] DEBUG: 11360: Disabling sleep skipping.
2026-05-28 20:03:58,604 [root] DEBUG: 11360: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:03:58,616 [root] DEBUG: 11360: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:03:58,619 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:03:58,621 [root] DEBUG: 11360: Monitor initialised: 64-bit capemon loaded in process 11360 at 0x00007FFEAF1A0000, thread 11364, image base 0x00007FF6868D0000, stack from 0x0000002788DB4000-0x0000002788DC0000
2026-05-28 20:03:58,622 [root] DEBUG: 11360: Commandline: C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
2026-05-28 20:03:58,632 [root] DEBUG: 11360: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:03:58,653 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:03:58,654 [root] DEBUG: 11360: set_hooks: Unable to hook LockResource
2026-05-28 20:03:58,660 [root] DEBUG: 11360: Hooked 627 out of 628 functions
2026-05-28 20:03:58,661 [root] DEBUG: 11360: Syscall hook installed, syscall logging level 1
2026-05-28 20:03:58,666 [root] DEBUG: 11360: RestoreHeaders: Restored original import table.
2026-05-28 20:03:58,668 [root] INFO: Loaded monitor into process with pid 11360
2026-05-28 20:03:58,669 [root] DEBUG: 11360: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6868D1349, thread 11364).
2026-05-28 20:03:58,670 [root] DEBUG: 11360: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:03:58,671 [root] DEBUG: 11360: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:03:58,673 [root] DEBUG: 11360: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:03:58,674 [root] DEBUG: 11360: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:03:58,677 [root] DEBUG: 11360: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:03:58,690 [root] DEBUG: 11360: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:03:58,704 [root] DEBUG: 11360: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:03:58,704 [root] DEBUG: 11360: DLL loaded at 0x00007FFED81B0000: C:\Windows\System32\thumbcache (0x66000 bytes).
2026-05-28 20:03:58,711 [root] DEBUG: 11360: DLL loaded at 0x00007FFEEB280000: C:\Windows\system32\propsys (0xf6000 bytes).
2026-05-28 20:04:00,881 [root] DEBUG: 4372: api-cap: RegQueryValueExW hook disabled due to count: 5000
2026-05-28 20:04:01,193 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 12556: C:\Windows\System32\rundll32.exe, ImageBase: 0x00007FF6C5DC0000
2026-05-28 20:04:01,194 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12556
2026-05-28 20:04:01,194 [lib.api.process] INFO: Monitor config for process 12556: C:\6lreqs2g\dll\12556.ini
2026-05-28 20:04:01,196 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:01,199 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:01,204 [root] DEBUG: Loader: Injecting process 12556 (thread 12560) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:01,205 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:04:01,206 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:01,207 [lib.api.process] INFO: Injected into 64-bit <Process 12556 rundll32.exe>
2026-05-28 20:04:01,209 [root] INFO: Announced 64-bit process name: rundll32.exe pid: 12556
2026-05-28 20:04:01,209 [lib.api.process] INFO: Monitor config for process 12556: C:\6lreqs2g\dll\12556.ini
2026-05-28 20:04:01,210 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:01,213 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:01,217 [root] DEBUG: Loader: Injecting process 12556 (thread 12560) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:01,217 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:04:01,218 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:01,219 [lib.api.process] INFO: Injected into 64-bit <Process 12556 rundll32.exe>
2026-05-28 20:04:01,225 [root] DEBUG: 12556: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:04:01,226 [root] DEBUG: 12556: Interactive desktop enabled.
2026-05-28 20:04:01,226 [root] DEBUG: 12556: Dropped file limit defaulting to 100.
2026-05-28 20:04:01,228 [root] DEBUG: 12556: Disabling sleep skipping.
2026-05-28 20:04:01,229 [root] DEBUG: 12556: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:04:01,242 [root] DEBUG: 12556: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:04:01,243 [root] DEBUG: 12556: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 20:04:01,244 [root] DEBUG: 12556: Monitor initialised: 64-bit capemon loaded in process 12556 at 0x00007FFEAF1A0000, thread 12560, image base 0x00007FF6C5DC0000, stack from 0x0000008844074000-0x0000008844080000
2026-05-28 20:04:01,245 [root] DEBUG: 12556: Commandline: C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
2026-05-28 20:04:01,255 [root] DEBUG: 12556: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:04:01,280 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:04:01,281 [root] DEBUG: 12556: set_hooks: Unable to hook LockResource
2026-05-28 20:04:01,287 [root] DEBUG: 12556: Hooked 627 out of 628 functions
2026-05-28 20:04:01,289 [root] DEBUG: 12556: Syscall hook installed, syscall logging level 1
2026-05-28 20:04:01,293 [root] DEBUG: 12556: RestoreHeaders: Restored original import table.
2026-05-28 20:04:01,294 [root] INFO: Loaded monitor into process with pid 12556
2026-05-28 20:04:01,295 [root] DEBUG: 12556: caller_dispatch: Added region at 0x00007FF6C5DC0000 to tracked regions list (kernel32::SetUnhandledExceptionFilter returns to 0x00007FF6C5DC6D01, thread 12560).
2026-05-28 20:04:01,296 [root] DEBUG: 12556: YaraScan: Scanning 0x00007FF6C5DC0000, size 0x16100
2026-05-28 20:04:01,299 [root] DEBUG: 12556: ProcessImageBase: Main module image at 0x00007FF6C5DC0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:04:01,304 [root] DEBUG: 12556: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:04:01,306 [root] DEBUG: 12556: DLL loaded at 0x00007FFEF0BA0000: C:\Windows\System32\MSCTF (0x114000 bytes).
2026-05-28 20:04:01,307 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 12556, handle 0x2cb0: C:\Windows\System32\rundll32.exe
2026-05-28 20:04:01,311 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8990000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:04:01,312 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE8990000: C:\Windows\System32\WorkFoldersShell (0x3d000 bytes).
2026-05-28 20:04:01,314 [root] DEBUG: 4372: api-rate-cap: LdrpCallInitRoutine hook disabled due to rate
2026-05-28 20:04:01,320 [root] DEBUG: 12556: NtTerminateProcess hook: Attempting to dump process 12556
2026-05-28 20:04:01,321 [root] DEBUG: 12556: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:04:01,328 [root] INFO: Process with pid 12556 has terminated
2026-05-28 20:04:03,770 [root] INFO: Process with pid 11360 has terminated
2026-05-28 20:04:03,771 [root] DEBUG: 11360: NtTerminateProcess hook: Attempting to dump process 11360
2026-05-28 20:04:03,772 [root] DEBUG: 11360: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:04:40,763 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13168: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:04:40,765 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13168
2026-05-28 20:04:40,765 [lib.api.process] INFO: Monitor config for process 13168: C:\6lreqs2g\dll\13168.ini
2026-05-28 20:04:40,767 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:40,770 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:40,775 [root] DEBUG: Loader: Injecting process 13168 (thread 13172) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:40,776 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:04:40,777 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:40,781 [lib.api.process] INFO: Injected into 64-bit <Process 13168 dllhost.exe>
2026-05-28 20:04:40,782 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13168
2026-05-28 20:04:40,783 [lib.api.process] INFO: Monitor config for process 13168: C:\6lreqs2g\dll\13168.ini
2026-05-28 20:04:40,783 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:40,788 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:40,793 [root] DEBUG: Loader: Injecting process 13168 (thread 13172) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:40,794 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:04:40,799 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:40,802 [lib.api.process] INFO: Injected into 64-bit <Process 13168 dllhost.exe>
2026-05-28 20:04:40,803 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11516: C:\Windows\system32\wbem\wmiprvse.exe, ImageBase: 0x00007FF7D5630000
2026-05-28 20:04:40,804 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 11516
2026-05-28 20:04:40,805 [lib.api.process] INFO: Monitor config for process 11516: C:\6lreqs2g\dll\11516.ini
2026-05-28 20:04:40,808 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:40,812 [root] DEBUG: 13168: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:04:40,813 [root] DEBUG: 13168: Interactive desktop enabled.
2026-05-28 20:04:40,814 [root] DEBUG: 13168: Dropped file limit defaulting to 100.
2026-05-28 20:04:40,817 [root] DEBUG: 13168: Disabling sleep skipping.
2026-05-28 20:04:40,818 [root] DEBUG: 13168: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:04:40,829 [root] DEBUG: 13168: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:04:40,831 [root] DEBUG: 13168: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:04:40,833 [root] DEBUG: 13168: Monitor initialised: 64-bit capemon loaded in process 13168 at 0x00007FFEAF1A0000, thread 13172, image base 0x00007FF6868D0000, stack from 0x000000A8304F4000-0x000000A830500000
2026-05-28 20:04:40,834 [root] DEBUG: 13168: Commandline: C:\Windows\system32\DllHost.exe /Processid:{338B40F9-9D68-4B53-A793-6B9AA0C5F63B}
2026-05-28 20:04:40,844 [root] DEBUG: 13168: hook_api: LdrpCallInitRoutine export address 0x00007FFEF20499BC obtained via GetFunctionAddress
2026-05-28 20:04:40,867 [root] WARNING: b'Unable to create trampoline for LockResource, hook type 2'
2026-05-28 20:04:40,871 [root] DEBUG: 13168: set_hooks: Unable to hook LockResource
2026-05-28 20:04:40,876 [root] DEBUG: 13168: Hooked 627 out of 628 functions
2026-05-28 20:04:40,878 [root] DEBUG: 13168: Syscall hook installed, syscall logging level 1
2026-05-28 20:04:40,882 [root] DEBUG: 13168: RestoreHeaders: Restored original import table.
2026-05-28 20:04:40,883 [root] INFO: Loaded monitor into process with pid 13168
2026-05-28 20:04:40,884 [root] DEBUG: 13168: caller_dispatch: Added region at 0x00007FF6868D0000 to tracked regions list (ntdll::NtAllocateVirtualMemory returns to 0x00007FF6868D12F2, thread 13172).
2026-05-28 20:04:40,885 [root] DEBUG: 13168: YaraScan: Scanning 0x00007FF6868D0000, size 0x8026
2026-05-28 20:04:40,886 [root] DEBUG: 13168: ProcessImageBase: Main module image at 0x00007FF6868D0000 unmodified (entropy change 0.000000e+00)
2026-05-28 20:04:40,889 [root] DEBUG: 13168: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:04:40,891 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:04:40,894 [root] DEBUG: 13168: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:04:40,911 [root] DEBUG: 13168: DLL loaded at 0x00007FFEED0B0000: C:\Windows\system32\uxtheme (0x9e000 bytes).
2026-05-28 20:04:40,927 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEEBF0000: C:\Windows\system32\logoncli (0x43000 bytes).
2026-05-28 20:04:40,928 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEEBE0000: C:\Windows\system32\netutils (0xc000 bytes).
2026-05-28 20:04:40,930 [root] DEBUG: 13168: DLL loaded at 0x00007FFEE8D30000: C:\Windows\system32\dhcpcsvc (0x1d000 bytes).
2026-05-28 20:04:40,932 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEA8B0000: C:\Windows\system32\WINHTTP (0x10a000 bytes).
2026-05-28 20:04:40,933 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEE830000: C:\Windows\SYSTEM32\ntmarta (0x33000 bytes).
2026-05-28 20:04:40,934 [root] DEBUG: 13168: DLL loaded at 0x00007FFEF0190000: C:\Windows\System32\shcore (0xad000 bytes).
2026-05-28 20:04:40,936 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEEAD0000: C:\Windows\system32\IPHLPAPI (0x3b000 bytes).
2026-05-28 20:04:40,937 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEF5C0000: C:\Windows\system32\USERENV (0x2e000 bytes).
2026-05-28 20:04:40,938 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEF640000: C:\Windows\system32\profapi (0x25000 bytes).
2026-05-28 20:04:40,939 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEB240000: C:\Windows\system32\XmlLite (0x36000 bytes).
2026-05-28 20:04:40,940 [root] DEBUG: 13168: DLL loaded at 0x00007FFEEEB10000: C:\Windows\system32\DNSAPI (0xca000 bytes).
2026-05-28 20:04:40,941 [root] DEBUG: 13168: DLL loaded at 0x00007FFED4740000: C:\Windows\system32\domgmt (0x86000 bytes).
2026-05-28 20:04:40,944 [root] DEBUG: 13168: DLL loaded at 0x00007FFEF0990000: C:\Windows\System32\NSI (0x8000 bytes).
2026-05-28 20:04:40,950 [root] DEBUG: 13168: DLL loaded at 0x00007FFEE0FD0000: C:\Windows\System32\OneCoreCommonProxyStub (0x7f000 bytes).
2026-05-28 20:04:41,542 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:41,546 [root] DEBUG: Loader: Injecting process 11516 (thread 11552) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:41,547 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:04:41,548 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:41,549 [lib.api.process] INFO: Injected into 64-bit <Process 11516 WmiPrvSE.exe>
2026-05-28 20:04:41,551 [root] INFO: Announced 64-bit process name: WmiPrvSE.exe pid: 11516
2026-05-28 20:04:41,551 [lib.api.process] INFO: Monitor config for process 11516: C:\6lreqs2g\dll\11516.ini
2026-05-28 20:04:41,552 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:42,452 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:42,456 [root] DEBUG: Loader: Injecting process 11516 (thread 11552) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:42,457 [root] DEBUG: InjectDllViaIAT: This image has already been patched.
2026-05-28 20:04:42,458 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:42,459 [lib.api.process] INFO: Injected into 64-bit <Process 11516 WmiPrvSE.exe>
2026-05-28 20:04:42,466 [root] DEBUG: 11516: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:04:42,466 [root] DEBUG: 11516: Interactive desktop enabled.
2026-05-28 20:04:42,467 [root] DEBUG: 11516: Dropped file limit defaulting to 100.
2026-05-28 20:04:42,468 [root] DEBUG: 11516: Disabling sleep skipping.
2026-05-28 20:04:42,469 [root] DEBUG: 11516: Services hook set enabled
2026-05-28 20:04:42,472 [root] DEBUG: 11516: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:04:42,484 [root] DEBUG: 11516: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:04:42,484 [root] DEBUG: 11516: Monitor initialised: 64-bit capemon loaded in process 11516 at 0x00007FFEAF1A0000, thread 11552, image base 0x00007FF7D5630000, stack from 0x000000743A8A0000-0x000000743A8B0000
2026-05-28 20:04:42,485 [root] DEBUG: 11516: Commandline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
2026-05-28 20:04:42,496 [root] DEBUG: 11516: Hooked 69 out of 69 functions
2026-05-28 20:04:42,499 [root] DEBUG: 11516: RestoreHeaders: Restored original import table.
2026-05-28 20:04:42,500 [root] INFO: Loaded monitor into process with pid 11516
2026-05-28 20:04:42,503 [root] DEBUG: 11516: DLL loaded at 0x00007FFEED5F0000: C:\Windows\SYSTEM32\kernel.appcore (0x12000 bytes).
2026-05-28 20:04:42,504 [root] DEBUG: 11516: DLL loaded at 0x00007FFEEFEE0000: C:\Windows\System32\bcryptPrimitives (0x82000 bytes).
2026-05-28 20:04:42,506 [root] DEBUG: 11516: DLL loaded at 0x00007FFEF0740000: C:\Windows\System32\clbcatq (0xa9000 bytes).
2026-05-28 20:04:42,509 [lib.api.process] INFO: Monitor config for process 7112: C:\6lreqs2g\dll\7112.ini
2026-05-28 20:04:42,510 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:04:42,516 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:04:42,522 [root] DEBUG: Loader: Injecting process 7112 with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:42,524 [root] DEBUG: 7112: Python path set to 'C:\Users\admin\AppData\Local\Python\pythoncore-3.14-64'.
2026-05-28 20:04:42,526 [root] DEBUG: 7112: Disabling sleep skipping.
2026-05-28 20:04:42,527 [root] DEBUG: 7112: Interactive desktop enabled.
2026-05-28 20:04:42,528 [root] DEBUG: 7112: Dropped file limit defaulting to 100.
2026-05-28 20:04:42,528 [root] DEBUG: 7112: Services hook set enabled
2026-05-28 20:04:42,531 [root] DEBUG: 7112: YaraInit: Compiled rules loaded from existing file C:\6lreqs2g\data\yara\capemon.yac
2026-05-28 20:04:42,543 [root] DEBUG: 7112: RtlInsertInvertedFunctionTable 0x00007FFEF204090E, LdrpInvertedFunctionTableSRWLock 0x00007FFEF219D4F0
2026-05-28 20:04:42,544 [root] DEBUG: 7112: Monitor initialised: 64-bit capemon loaded in process 7112 at 0x00007FFEAF1A0000, thread 13564, image base 0x00007FF6A8D80000, stack from 0x000000B5FFF74000-0x000000B5FFF80000
2026-05-28 20:04:42,545 [root] DEBUG: 7112: Commandline: C:\Windows\system32\svchost.exe -k netsvcs -p
2026-05-28 20:04:42,557 [root] DEBUG: 7112: Hooked 69 out of 69 functions
2026-05-28 20:04:42,559 [root] INFO: Loaded monitor into process with pid 7112
2026-05-28 20:04:42,561 [root] DEBUG: InjectDllViaThread: Successfully injected Dll into process via RtlCreateUserThread.
2026-05-28 20:04:42,561 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:04:42,563 [lib.api.process] INFO: Injected into 64-bit <Process 7112 svchost.exe>
2026-05-28 20:04:44,565 [root] DEBUG: 11516: DLL loaded at 0x00007FFEDD9B0000: C:\Windows\system32\wbem\wbemprox (0x11000 bytes).
2026-05-28 20:04:44,569 [root] DEBUG: 11516: DLL loaded at 0x00007FFED9650000: C:\Windows\system32\wbem\wbemsvc (0x14000 bytes).
2026-05-28 20:04:44,577 [root] DEBUG: 11516: DLL loaded at 0x00007FFEDFDE0000: C:\Windows\system32\wbem\wmiutils (0x28000 bytes).
2026-05-28 20:04:44,588 [root] DEBUG: 11516: DLL loaded at 0x00007FFEEF570000: C:\Windows\SYSTEM32\powrprof (0x4b000 bytes).
2026-05-28 20:04:44,588 [root] DEBUG: 11516: DLL loaded at 0x00007FFEADBB0000: C:\Windows\SYSTEM32\framedynos (0x52000 bytes).
2026-05-28 20:04:44,589 [root] DEBUG: 11516: DLL loaded at 0x00007FFEADC10000: C:\Windows\system32\wbem\cimwin32 (0x20c000 bytes).
2026-05-28 20:04:44,590 [root] DEBUG: 11516: DLL loaded at 0x00007FFEEF550000: C:\Windows\SYSTEM32\UMPDC (0x12000 bytes).
2026-05-28 20:04:44,597 [root] DEBUG: 11516: DLL loaded at 0x0000021400600000: C:\Windows\SYSTEM32\WMI (0x3000 bytes).
2026-05-28 20:04:44,598 [root] DEBUG: 11516: DLL loaded at 0x00007FFEEA840000: C:\Windows\SYSTEM32\wmiclnt (0x11000 bytes).
2026-05-28 20:04:44,599 [root] DEBUG: 11516: CreateThreadBreakpoints: Failed to open thread and get a handle.
2026-05-28 20:04:45,974 [root] INFO: Process with pid 13168 has terminated
2026-05-28 20:04:45,975 [root] DEBUG: 13168: NtTerminateProcess hook: Attempting to dump process 13168
2026-05-28 20:04:45,977 [root] DEBUG: 13168: DoProcessDump: Skipping process dump as code is identical on disk.
2026-05-28 20:04:47,103 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4790000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:04:47,104 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4790000: C:\Windows\System32\wscinterop (0x3d000 bytes).
2026-05-28 20:04:47,106 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:04:47,108 [root] DEBUG: 4372: DLL loaded at 0x00007FFEE1490000: C:\Windows\System32\WSCAPI (0x4d000 bytes).
2026-05-28 20:04:47,115 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4770000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:04:47,115 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4770000: C:\Windows\System32\wscui.cpl (0x19000 bytes).
2026-05-28 20:04:47,145 [root] DEBUG: 4372: DLL loaded at 0x00007FFEADBB0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:04:47,146 [root] DEBUG: 4372: DLL loaded at 0x00007FFEADBB0000: C:\Windows\System32\framedynos (0x52000 bytes).
2026-05-28 20:04:47,148 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:04:47,151 [root] DEBUG: 4372: DLL loaded at 0x00007FFEED410000: C:\Windows\System32\wer (0xde000 bytes).
2026-05-28 20:04:47,152 [root] DEBUG: 4372: DLL loaded at 0x00007FFEADAD0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:04:47,156 [root] DEBUG: 4372: DLL loaded at 0x00007FFEADAD0000: C:\Windows\System32\werconcpl (0xde000 bytes).
2026-05-28 20:04:47,201 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4750000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:04:47,202 [root] DEBUG: 4372: DLL loaded at 0x00007FFED4750000: C:\Windows\System32\hcproviders (0x14000 bytes).
2026-05-28 20:04:47,212 [root] DEBUG: 4372: DLL loaded at 0x00007FFEAD9E0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:04:47,213 [root] DEBUG: 4372: DLL loaded at 0x00007FFEAD9E0000: C:\Windows\System32\ieproxy (0xee000 bytes).
2026-05-28 20:05:02,809 [root] DEBUG: 4372: api-cap: NtQueryInformationToken hook disabled due to count: 5000
2026-05-28 20:05:03,212 [root] DEBUG: 4372: api-cap: RegOpenKeyExW hook disabled due to count: 5000
2026-05-28 20:05:18,900 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 3856 (handle 0x28bc): 0x00007FF66D090000.
2026-05-28 20:05:18,902 [root] DEBUG: 4372: OpenProcessHandler: Injection info created for process 3856, handle 0x28bc: C:\Windows\System32\conhost.exe
2026-05-28 20:05:18,938 [root] DEBUG: 4372: api-cap: RegCloseKey hook disabled due to count: 5000
2026-05-28 20:05:18,938 [root] DEBUG: 4372: api-cap: RegCloseKey hook disabled due to count: 5001
2026-05-28 20:05:22,136 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 6220 (handle 0x26b0): 0x00007FF741AF0000.
2026-05-28 20:05:22,153 [root] DEBUG: 4372: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 20:05:22,155 [root] DEBUG: 4372: api-rate-cap: NtQueryKey hook disabled due to rate
2026-05-28 20:05:22,231 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 3076: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,235 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3076
2026-05-28 20:05:22,236 [lib.api.process] INFO: Monitor config for process 3076: C:\6lreqs2g\dll\3076.ini
2026-05-28 20:05:22,239 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,245 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,250 [root] DEBUG: Loader: Injecting process 3076 (thread 3428) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,251 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,251 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,253 [lib.api.process] INFO: Injected into 64-bit <Process 3076 dllhost.exe>
2026-05-28 20:05:22,255 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 3076
2026-05-28 20:05:22,255 [lib.api.process] INFO: Monitor config for process 3076: C:\6lreqs2g\dll\3076.ini
2026-05-28 20:05:22,256 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,260 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,268 [root] DEBUG: Loader: Injecting process 3076 (thread 3428) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,271 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,272 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,273 [lib.api.process] INFO: Injected into 64-bit <Process 3076 dllhost.exe>
2026-05-28 20:05:22,281 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13216: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,282 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13216
2026-05-28 20:05:22,283 [lib.api.process] INFO: Monitor config for process 13216: C:\6lreqs2g\dll\13216.ini
2026-05-28 20:05:22,284 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,288 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,294 [root] DEBUG: Loader: Injecting process 13216 (thread 1436) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,302 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,303 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,304 [lib.api.process] INFO: Injected into 64-bit <Process 13216 dllhost.exe>
2026-05-28 20:05:22,306 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13216
2026-05-28 20:05:22,306 [lib.api.process] INFO: Monitor config for process 13216: C:\6lreqs2g\dll\13216.ini
2026-05-28 20:05:22,308 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,316 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,321 [root] DEBUG: Loader: Injecting process 13216 (thread 1436) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,322 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,323 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,324 [lib.api.process] INFO: Injected into 64-bit <Process 13216 dllhost.exe>
2026-05-28 20:05:22,328 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 11192: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,333 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11192
2026-05-28 20:05:22,334 [lib.api.process] INFO: Monitor config for process 11192: C:\6lreqs2g\dll\11192.ini
2026-05-28 20:05:22,335 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,342 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,348 [root] DEBUG: Loader: Injecting process 11192 (thread 8880) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,349 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,350 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,352 [lib.api.process] INFO: Injected into 64-bit <Process 11192 dllhost.exe>
2026-05-28 20:05:22,355 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 11192
2026-05-28 20:05:22,356 [lib.api.process] INFO: Monitor config for process 11192: C:\6lreqs2g\dll\11192.ini
2026-05-28 20:05:22,357 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,362 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,367 [root] DEBUG: Loader: Injecting process 11192 (thread 8880) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,368 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,368 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,370 [lib.api.process] INFO: Injected into 64-bit <Process 11192 dllhost.exe>
2026-05-28 20:05:22,378 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 13308: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,380 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13308
2026-05-28 20:05:22,381 [lib.api.process] INFO: Monitor config for process 13308: C:\6lreqs2g\dll\13308.ini
2026-05-28 20:05:22,382 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,386 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,394 [root] DEBUG: Loader: Injecting process 13308 (thread 12616) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,396 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,398 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,399 [lib.api.process] INFO: Injected into 64-bit <Process 13308 dllhost.exe>
2026-05-28 20:05:22,401 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 13308
2026-05-28 20:05:22,402 [lib.api.process] INFO: Monitor config for process 13308: C:\6lreqs2g\dll\13308.ini
2026-05-28 20:05:22,403 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,408 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,412 [root] DEBUG: Loader: Injecting process 13308 (thread 12616) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,413 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,414 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,415 [lib.api.process] INFO: Injected into 64-bit <Process 13308 dllhost.exe>
2026-05-28 20:05:22,420 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 800: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,423 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 800
2026-05-28 20:05:22,425 [lib.api.process] INFO: Monitor config for process 800: C:\6lreqs2g\dll\800.ini
2026-05-28 20:05:22,426 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,431 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,437 [root] DEBUG: Loader: Injecting process 800 (thread 444) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,438 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,441 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,443 [lib.api.process] INFO: Injected into 64-bit <Process 800 dllhost.exe>
2026-05-28 20:05:22,446 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 800
2026-05-28 20:05:22,447 [lib.api.process] INFO: Monitor config for process 800: C:\6lreqs2g\dll\800.ini
2026-05-28 20:05:22,447 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,451 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,458 [root] DEBUG: Loader: Injecting process 800 (thread 444) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,459 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,460 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,462 [lib.api.process] INFO: Injected into 64-bit <Process 800 dllhost.exe>
2026-05-28 20:05:22,466 [root] DEBUG: 848: CreateProcessHandler: Injection info set for new process 4360: C:\Windows\system32\DllHost.exe, ImageBase: 0x00007FF6868D0000
2026-05-28 20:05:22,469 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4360
2026-05-28 20:05:22,470 [lib.api.process] INFO: Monitor config for process 4360: C:\6lreqs2g\dll\4360.ini
2026-05-28 20:05:22,471 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,476 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,480 [root] DEBUG: Loader: Injecting process 4360 (thread 1336) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,481 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,482 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,484 [lib.api.process] INFO: Injected into 64-bit <Process 4360 dllhost.exe>
2026-05-28 20:05:22,486 [root] INFO: Announced 64-bit process name: dllhost.exe pid: 4360
2026-05-28 20:05:22,489 [lib.api.process] INFO: Monitor config for process 4360: C:\6lreqs2g\dll\4360.ini
2026-05-28 20:05:22,490 [lib.api.process] INFO: Option 'interactive' with value '1' sent to monitor
2026-05-28 20:05:22,495 [lib.api.process] INFO: 64-bit DLL to inject is C:\6lreqs2g\dll\cPdiizJ.dll, loader C:\6lreqs2g\bin\LSGeBGIE.exe
2026-05-28 20:05:22,502 [root] DEBUG: Loader: Injecting process 4360 (thread 1336) with C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,503 [root] DEBUG: InjectDllViaIAT: Successfully patched IAT.
2026-05-28 20:05:22,504 [root] DEBUG: Successfully injected DLL C:\6lreqs2g\dll\cPdiizJ.dll.
2026-05-28 20:05:22,505 [lib.api.process] INFO: Injected into 64-bit <Process 4360 dllhost.exe>
2026-05-28 20:05:22,667 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
2026-05-28 20:05:22,673 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
2026-05-28 20:05:22,952 [root] DEBUG: 4372: api-cap: RtlSetCurrentTransaction hook disabled due to count: 5000
2026-05-28 20:05:22,969 [root] DEBUG: 4372: api-cap: NtOpenKeyEx hook disabled due to count: 5000
2026-05-28 20:05:23,244 [root] DEBUG: 4372: api-cap: CoCreateInstance hook disabled due to count: 5000
2026-05-28 20:05:23,320 [root] INFO: Added new file to list with pid 4372 and path C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
2026-05-28 20:05:25,866 [root] DEBUG: 4372: OpenProcessHandler: Image base for process 6028 (handle 0x54c): 0x00007FF6174D0000.
| Name | Label | Manager | Started On | Shutdown On | Route |
|---|---|---|---|---|---|
| cuckoo1 | cuckoo1 | KVM | 2026-05-28 20:03:28 | 2026-05-28 20:05:39 | none |
| File Name |
test-serial.ps1
|
|---|---|
| File Type | ASCII text |
| File Size | 3228 bytes |
| MD5 | df6e225c6f41d7a26e86e884a31a0e5c |
| SHA1 | e4ad10ef724b9aebf09c6a8bc56c55ea47b1d18d |
| SHA256 | 8a19e22f8137fe44bef39408f730396abad362f317cfb1eae8710c71352095ae VT MWDB Bazaar |
| SHA3-384 | 5215b80edc5d9e5df0b1f267a28898b9cf8573b269c0e9a1bf326bda5f97d5a912d37a84cbf52577290e3850078d5729 |
| CRC32 | D0ABF095 |
| TLSH | T13761477197058231C442315A86CAF50BF739712129DA9980FEFC83999F9E133D77535B |
| Ssdeep | 48:DEjfIoF9I8czF9IhnmKEuGxs2Jl2j53I+4aus+1Aj3IYKBH7ufjAXN6lTdN:DEjlFdczFeOsaEqdTDAkrh7ufjA9mP |
Add-Type @"
using System;
using System.Runtime.InteropServices;
public class VolTest {
[DllImport("kernel32.dll", CharSet=CharSet.Unicode, SetLastError=true)]
public static extern bool GetVolumeInformationByHandleW(
IntPtr hFile, System.Text.StringBuilder lpVolumeNameBuffer, uint nVolumeNameSize,
out uint lpVolumeSerialNumber, out uint lpMaxComponentLen,
out uint lpFileSystemFlags, System.Text.StringBuilder lpFileSystemName, uint nFileSystemNameSize);
[DllImport("kernel32.dll", CharSet=CharSet.Unicode, SetLastError=true)]
public static extern bool GetVolumeInformationW(
string lpRootPathName, System.Text.StringBuilder lpVolumeNameBuffer, uint nVolumeNameSize,
out uint lpVolumeSerialNumber, out uint lpMaxComponentLen,
out uint lpFileSystemFlags, System.Text.StringBuilder lpFileSystemName, uint nFileSystemNameSize);
[DllImport("kernel32.dll", CharSet=CharSet.Unicode, SetLastError=true)]
public static extern IntPtr CreateFile(string lpFileName, uint dwAccess, uint dwShare,
IntPtr sec, uint dwCreation, uint dwFlags, IntPtr tmpl);
[DllImport("kernel32.dll")] public static extern bool CloseHandle(IntPtr h);
public const uint GENERIC_READ = 0x80000000;
public const uint FILE_SHARE_READ = 1; public const uint FILE_SHARE_WRITE = 2;
public const uint OPEN_EXISTING = 3;
public const uint FILE_FLAG_BACKUP_SEMANTICS = 0x02000000;
}
"@
$out = @()
# Test 1: GetVolumeInformationW (path-based)
$volName = New-Object System.Text.StringBuilder 256
$fsName = New-Object System.Text.StringBuilder 256
$serial = 0; $maxLen = 0; $flags = 0
$ok = [VolTest]::GetVolumeInformationW("C:\", $volName, 256, [ref]$serial, [ref]$maxLen, [ref]$flags, $fsName, 256)
$out += "GetVolumeInformationW(C:\): serial=0x{0:X8} ok={1}" -f $serial, $ok
# Test 2: GetVolumeInformationByHandleW on C:\ directory
$h = [VolTest]::CreateFile("C:\", [VolTest]::GENERIC_READ,
[VolTest]::FILE_SHARE_READ -bor [VolTest]::FILE_SHARE_WRITE,
[IntPtr]::Zero, [VolTest]::OPEN_EXISTING, [VolTest]::FILE_FLAG_BACKUP_SEMANTICS, [IntPtr]::Zero)
$volName2 = New-Object System.Text.StringBuilder 256
$fsName2 = New-Object System.Text.StringBuilder 256
$serial2 = 0; $maxLen2 = 0; $flags2 = 0
$ok2 = [VolTest]::GetVolumeInformationByHandleW($h, $volName2, 256, [ref]$serial2, [ref]$maxLen2, [ref]$flags2, $fsName2, 256)
[VolTest]::CloseHandle($h) | Out-Null
$out += "GetVolumeInformationByHandleW(C:\): serial=0x{0:X8} ok={1}" -f $serial2, $ok2
# Test 3: ByHandleW on a real file
$h2 = [VolTest]::CreateFile("C:\Windows\notepad.exe", [VolTest]::GENERIC_READ,
[VolTest]::FILE_SHARE_READ -bor [VolTest]::FILE_SHARE_WRITE,
[IntPtr]::Zero, [VolTest]::OPEN_EXISTING, 0, [IntPtr]::Zero)
$volName3 = New-Object System.Text.StringBuilder 256
$fsName3 = New-Object System.Text.StringBuilder 256
$serial3 = 0; $maxLen3 = 0; $flags3 = 0
$ok3 = [VolTest]::GetVolumeInformationByHandleW($h2, $volName3, 256, [ref]$serial3, [ref]$maxLen3, [ref]$flags3, $fsName3, 256)
[VolTest]::CloseHandle($h2) | Out-Null
$out += "GetVolumeInformationByHandleW(notepad.exe): serial=0x{0:X8} ok={1}" -f $serial3, $ok3
$out | Tee-Object -FilePath "C:\serial_test_results.txt"
Seek in progress...
| Direct | IP | Country Name | ASN |
|---|---|---|---|
| Y | 13.70.178.62 [VT] | unknown | - |
| Y | 13.107.213.31 [VT] | unknown | - |
| Y | 150.171.28.12 [VT] | unknown | - |
| Y | 162.159.128.235 [VT] | unknown | - |
| Y | 23.209.40.114 [VT] | unknown | - |
| Y | 162.159.128.233 [VT] | unknown | - |
| N | 162.159.133.234 [VT] | unknown | - |
| N | 162.159.130.234 [VT] | unknown | - |
| Y | 199.232.215.52 [VT] | unknown | - |
| Y | 23.202.165.41 [VT] | unknown | - |
| Y | 23.202.165.215 [VT] | unknown | - |
| Y | 23.216.117.82 [VT] | unknown | - |
| Y | 162.159.130.233 [VT] | unknown | - |
| Y | 162.159.134.233 [VT] | unknown | - |
| Y | 172.172.255.217 [VT] | unknown | - |
| Y | 20.190.167.20 [VT] | unknown | - |
| Y | 162.254.194.57 [VT] | unknown | - |
| Y | 199.232.211.52 [VT] | unknown | - |
| Y | 162.254.195.69 [VT] | unknown | - |
| Y | 162.254.195.75 [VT] | unknown | - |
| Y | 103.10.125.23 [VT] | unknown | - |
| Y | 103.10.125.22 [VT] | unknown | - |
| N | 23.216.106.59 [VT] | unknown | - |
| N | 149.135.84.155 [VT] | unknown | - |
| Name | Response | Post-Analysis Lookup |
|---|---|---|
| api.steampowered.com [VT] | A 23.216.106.59 [VT] | 23.216.106.59 [VT] |
| ipv6check-http.steamserver.net [VT] |
CNAME http.ipv6check.akadns.net
[VT]
CNAME syd.http.ipv6check.akadns.net [VT] |
|
| steamconnecttest.com [VT] |
A 149.135.84.160
[VT]
A 149.135.84.155 [VT] |
23.62.157.117 [VT] |
| disabled.invalid [VT] | NXDOMAIN | |
| p2p-syd1.discovery.steamserver.net [VT] |
A 103.10.125.24
[VT]
A 103.10.125.42 [VT] |
103.10.125.24 [VT] |
| gateway-us-east1-d.discord.gg [VT] |
A 162.159.133.234
[VT]
A 162.159.135.234 [VT] A 162.159.130.234 [VT] A 162.159.134.234 [VT] A 162.159.136.234 [VT] |
162.159.130.234 [VT] |
| client-update.akamai.steamstatic.com [VT] |
CNAME client-update.akamai.steamstatic.com.akamaized.net
[VT]
A 104.115.81.74 [VT] CNAME a78.dscw27.akamai.net [VT] A 23.209.183.185 [VT] |
23.62.157.77 [VT] |
No results found.
No behavioral analysis data available.
No dropped files found.
No CAPE payloads found.